Roamance Privacy and Personal Data Protection Policy
This privacy and personal data protection policy (the "Policy") has been drawn up in order to inform, in a clear, complete and transparent manner, any concerned person about how ROAMANCE collects, uses, stores, protects and, where applicable, transmits their personal data in the context of the use of the ROAMANCE website, the ROAMANCE mobile application and the eSIM services offered by ROAMANCE.
ROAMANCE attaches particular importance to the protection of personal data and undertakes to process it in compliance with applicable regulations, in particular Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR"), as well as amended French law no. 78-17 of 6 January 1978, known as the French Data Protection Act (Loi Informatique et Libertés).
This Policy is intended to apply to any natural person concerned by a processing activity carried out by ROAMANCE, in particular website visitors, application users, customers, prospects, as well as any person contacting ROAMANCE.
1. Data controller
The controller of the personal data collected in the context of the website, the mobile application and the services marketed under the ROAMANCE brand is FRANCE NUMERIQUE, the sole entity having legal personality and determining the purposes and means of the processing activities carried out.
The ROAMANCE brand is a brand published and operated by FRANCE NUMERIQUE. It does not constitute a separate legal entity.
Consequently, any reference in this Policy to "ROAMANCE", "we", "our" or "us" shall be understood as referring to FRANCE NUMERIQUE, acting under the ROAMANCE brand and whose contact details are as follows:
FRANCE NUMERIQUE
150 boulevard Victor Hugo - 93400 - Saint-Ouen-sur-Seine
SIRET no. 84036174500010 - RCS Bobigny
2. Scope of the Policy
This Policy applies to the processing of personal data carried out in the context of:
- browsing the ROAMANCE website
- the creation and management of a customer account
- the subscription to an eSIM and/or a Data Plan
- the purchase of top-ups, in particular by QR code
- the installation, activation and use of ROAMANCE services
- the consumption monitoring accessible exclusively via the ROAMANCE application
- access to the order history accessible exclusively via the ROAMANCE application
- access to customer support accessible exclusively via the ROAMANCE application
- payment management
- the sending of transactional, technical, commercial or informational communications
- the handling of requests for the exercise of rights and any disputes
3. Categories of personal data collected
In the context of its activities, ROAMANCE may collect and process the following categories of personal data:
3.1 Identification data
- last name
- first name
- e-mail address
- telephone number
- customer ID
- login credentials
- technical identifiers associated with the account or the service
3.2 Customer account data
- encrypted password or data necessary for authentication
- account preferences
- language;
- history of account creation, modification or deletion
3.3 Data related to orders and the commercial relationship
- order number
- date and time of purchase
- type of subscribed offer
- country or covered area
- data volume
- validity period
- amount paid
- payment currency
- order status
- history of purchases and top-ups
3.4 Payment data
ROAMANCE only collects the data strictly necessary for the management of the payment and the proof of the transaction.
Depending on the case, the following may be processed:
- type of means of payment used
- transaction identifier
- payment status
- payment token
- last four digits of the bank card, where this information is transmitted by the payment provider
- partial expiration date or equivalent proof of the registered means of payment
Payments may be made via:
- Carte Bleue VISA
- Carte Bleue MASTERCARD
- Apple Pay
- Google Pay
All transactions are payable in euros (€).
ROAMANCE does not intend to retain the full bank card number or the visual cryptogram, unless this is technically operated by an accredited payment provider acting in compliance with applicable regulations.
3.5 Technical and connection data
- IP address
- connection logs
- date and time of connection
- type of device
- operating system
- application version
- type and version of browser
- device language
- technical identifiers of the device or the application, where necessary for the operation of the service
- data relating to security, authentication and fraud prevention
3.6 Data related to the use of the eSIM service
- data relating to the installation and activation of the eSIM
- eSIM identifier or technical identifier associated with the line, where necessary for the operation of the service
- information relating to the subscribed data plan
- data relating to top-ups by QR code
- information related to the status of the line
- information relating to consumption monitoring
- remaining validity period
- volume of data consumed and remaining
- functional usage history available in the application
3.7 Data from exchanges with customer support
As customer support is accessible exclusively via the ROAMANCE application, ROAMANCE may process
- the content of requests submitted via the application
- documents or screenshots transmitted by the user
- exchanges related to the resolution of an incident
- technical information necessary for diagnosis
3.8 Prospecting and communication data
- e-mail address
- communication preferences
- consents obtained
- history of sending, opening or interacting with electronic communications where such processing is carried out in compliance with applicable regulations
3.9 Data collected via cookies and trackers
Certain data may be collected through cookies, SDKs or other trackers placed on the website or in the application, depending on the choices expressed by the user and under the conditions provided for by the ROAMANCE cookie policy.
4. Method of collecting personal data
The personal data processed by ROAMANCE is collected in various ways.
4.1 Data provided directly by the concerned person
ROAMANCE collects data transmitted directly by the user or customer, in particular during:
- the creation of the account
- logging into the account
- subscription to an eSIM offer
- the purchase of a top-up
- payment
- the use of an online form
- a request submitted to customer support via the application
- the exercise of rights regarding personal data
4.2 Data collected automatically during use of the site, application or service
ROAMANCE collects certain data automatically upon access to the website, the application or the service, in particular:
- technical connection data
- logs
- information necessary for the proper technical functioning of the service
- data enabling usage monitoring, securing of the platform and improving the user experience
4.3 Data collected from providers or partners
ROAMANCE may receive certain data from:
- its payment providers
- its technical providers
- its operator partners or network infrastructure providers
- its analytics, security, hosting or support tools
4.4 Data collected from public sources
ROAMANCE may, on an occasional basis, process data made public by the concerned persons or lawfully accessible, where necessary for the management of the commercial relationship, the prevention of fraud or the defense of its rights.
5. Mandatory or optional nature of data
Where collection is carried out through a form or a subscription flow, ROAMANCE indicates, where possible, the data whose provision is mandatory.
Failing the provision of certain indispensable data, ROAMANCE may be unable:
- to create the user account
- to process an order
- to provide an eSIM
- to enable activation of the service
- to ensure service monitoring or customer support
- to respond to a request submitted by the user
6. Purposes, legal bases and retention periods
ROAMANCE processes personal data only for specified, explicit and legitimate purposes.
The main purposes, legal bases and retention periods are set out below.
6.1 Management of the customer account and provision of the service
Purposes:
- creation, management, securing and deletion of the account
- identification and authentication of users
- subscription to eSIM offers
- delivery, installation, activation and management of the eSIM
- management of top-ups, in particular by QR code
- access to consumption monitoring in the application
- access to the order history in the application
- operational management of the service
Categories of data:
Identification data, account data, technical data, order-related data, data related to the use of the eSIM service.
Legal basis:
Performance of the contract.
Retention period:
The data is retained for the entire duration of the contractual relationship, then archived for a period of five (5) years from the end of this relationship for evidentiary and complaint-handling purposes, unless a legal obligation or particular necessity justifies a longer period.
6.2 Management of payments, invoicing and accounting
Purposes:
- processing and securing of payments
- transaction management
- issuance and retention of supporting documents
- accounting and tax management
Categories of data:
Identification data, order data, payment data, transaction data.
Legal basis:
Performance of the contract and legal obligations.
Retention period:
The data necessary for invoicing and accounting is retained for the applicable legal period, in particular ten (10) years where accounting or tax regulations so require.
6.3 Customer relationship monitoring and support
Purposes:
- processing of information requests
- technical assistance
- handling of complaints
- handling of service-related incidents
Categories of data:
Identification data, technical data, connection data, data related to the service, content of exchanges with support.
Legal basis:
Performance of the contract; legitimate interest of ROAMANCE in ensuring the quality and continuity of the service.
Retention period:
For the duration of the contractual relationship then five (5) years from its end, unless longer retention is necessary in the event of litigation.
6.4 Consumption monitoring and usage information
Purposes:
- display in the application of the volume of data consumed and remaining
- display of the validity period
- monitoring of top-ups and the status of the line
- informing the user about the use of their plan
Categories of data:
Data related to the use of the eSIM service, technical identifiers, order data, technical data.
Legal basis:
Performance of the contract.
Retention period:
For the duration of the validity of the service, then archived for a maximum period of five (5) years from the end of the contractual relationship, unless otherwise required.
6.5 Security, fraud prevention and protection of systems
Purposes:
- detection, prevention and management of fraud attempts
- securing of accounts, payments, authentication flows and services
- retention of evidence in the event of an anomaly, attack or unlawful use
Categories of data:
Connection data, IP address, technical logs, usage data, payment-related data, technical identifiers.
Legal basis:
Legitimate interest of ROAMANCE in ensuring the security of its services and preventing fraud.
Retention period:
- connection logs: six (6) months from their collection, unless longer retention is necessary in the event of a security incident
- IP address and security-related data: up to one (1) year, unless evidentiary necessity or a particular legal obligation applies
6.6 Transactional and technical communications
Purposes:
- sending of e-mails or notifications related to account creation
- order confirmation
- information relating to activation, top-up or service status
- messages relating to account security
- information essential to the performance of the contract
Categories of data:
Identification data, order data, technical data, service-related data.
Legal basis:
Performance of the contract.
Retention period:
For the duration of the contractual relationship then five (5) years from its end for evidentiary purposes.
6.7 Commercial communications and prospecting
Purposes:
- sending of promotional offers
- information about ROAMANCE products or services
- customer loyalty and commercial engagement
- improvement of customer knowledge
Categories of data:
Identification data, order data, communication preferences.
Legal basis:
- consent, where required
- legitimate interest, where it concerns promoting analogous products or services to existing customers, in compliance with applicable regulations
Retention period:
- for prospects: three (3) years from the last contact emanating from the concerned person
- for customers: three (3) years from the end of the commercial relationship or the last relevant contact, unless prior opposition or withdrawal of consent
6.8 Compliance with legal obligations and management of disputes
Purposes:
- compliance with legal, regulatory and administrative obligations
- handling of requests for the exercise of rights
- management of pre-litigation and litigation
- retention of evidence
Categories of data:
All categories strictly necessary depending on the situation.
Legal basis:
Legal obligation; legitimate interest of ROAMANCE in defending its rights.
Retention period:
For the applicable legal limitation period, in particular five (5) years from the end of the contractual relationship, unless a longer legal period applies.
7. Recipients of personal data
Personal data is processed by authorized persons within ROAMANCE, within the limits of their respective duties and for the sole purposes described in this Policy.
It may also be transmitted, where necessary, to the following categories of recipients:
- authorized internal personnel of ROAMANCE
- hosting and IT outsourcing providers
- technical providers involved in the operation of the website, the application or the service
- payment providers and fraud-prevention partners
- operator partners and network infrastructure providers, to the strict extent necessary for the provision of the eSIM service
- analytics, communication, support or maintenance providers
- legal advisors, auditors, insurers or experts, where necessary
- administrative, judicial, tax or supervisory authorities, where required or permitted by law
- ROAMANCE does not sell personal data to third parties.
8. Transfers of data outside the European Union
Personal data is hosted and processed within the European Union.
ROAMANCE does not organize any transfer of data to a country located outside the European Union or the European Economic Area.
9. Data security and confidentiality
ROAMANCE implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks presented by the processing of personal data.
These measures aim in particular to protect the data against:
- accidental or unlawful destruction
- loss
- alteration
- unauthorized disclosure
- unauthorized access
- any unlawful or non-compliant processing
These measures may, in particular, include:
- management of access rights
- logging of accesses
- securing of passwords and authentication mechanisms
- encryption or pseudonymization where relevant
- securing of flows, servers, workstations and application environments
- backup, monitoring and incident management procedures
- raising awareness among persons authorized to process the data
Despite the efforts deployed, as no security system is completely infallible, ROAMANCE cannot guarantee absolute security. In the event of a personal data breach likely to result in a risk to the rights and freedoms of the concerned persons, ROAMANCE will act in accordance with applicable regulations.
10. Cookies and trackers
ROAMANCE may use cookies, SDKs, pixels and other trackers on the website and in the application, in particular to:
- ensure the technical functioning of the service
- remember certain choices or preferences
- measure audience and performance
- improve the user experience
- secure access
- carry out, where applicable, communication or personalization operations, subject to the choices expressed by the user
Where regulations so require, the placement or reading of trackers that are not strictly necessary is subject to the user's prior consent.
The detailed arrangements relating to these trackers are set out in ROAMANCE's cookie policy.
11. Rights of concerned persons
In accordance with applicable regulations, any concerned person has, depending on the case, the following rights:
- right of access to personal data concerning them
- right of rectification of inaccurate or incomplete data
- right to erasure of data, under the conditions provided for by the regulations
- right to restriction of processing
- right to data portability, where this right is applicable
- right to object to processing, on grounds relating to their particular situation, where the processing is based on legitimate interest
- right to object at any time to commercial prospecting
- right to withdraw consent at any time where the processing is based on consent
- right to define directives relating to the fate of their data after their death, in accordance with French law
Where reasonable doubt exists as to the identity of the requester, ROAMANCE may request additional information or proof of identity strictly necessary for verification.
12. Procedures for exercising rights
Any concerned person may exercise their rights by contacting ROAMANCE's Data Protection Officer (DPO):
- by e-mail at the following address: GDPR@roamance.io
- by postal mail at the following address: FRANCE NUMERIQUE - ROAMANCE Data Protection Officer - 150 boulevard Victor Hugo - 93400 - SAINT-OUEN-SUR-SEINE
ROAMANCE will endeavor to respond within the timeframes provided for by applicable regulations.
The concerned person also has the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL) (French data protection authority).
13. Minors' data
The ROAMANCE service is not intended to be used by unauthorized minors. In any event, where applicable regulations so require, use of the service by a minor presupposes the intervention or authorization of the holder of parental authority.
If ROAMANCE learns that personal data has been collected from a minor in disregard of the applicable rules, it will take the appropriate measures to delete it or restrict its processing as soon as possible.
14. Modifications to the policy
ROAMANCE may modify this Policy at any time in order to take into account:
- legal or regulatory developments
- recommendations from supervisory authorities
- case-law developments
- technical or functional changes to the website, the application or the service
In the event of a minor modification, the update date of this Privacy and Personal Data Protection Policy will be amended.
In the event of a substantial modification affecting in particular the purposes of the processing, the categories of data collected, the conditions for exercising rights or the arrangements for transferring data, ROAMANCE will inform the concerned persons by any appropriate means, in particular by a notice on the website, in the application and/or by e-mail.
The version of this Privacy and Personal Data Protection Policy in force is the one published on the website and/or in the application on the date of consultation.
15. Contact
For any question relating to this Policy or to how ROAMANCE processes personal data, you may contact ROAMANCE Customer Service by e-mail at customer@roamance.io or by post at the following address:
FRANCE NUMERIQUE
ROAMANCE Customer Service
150 boulevard Victor Hugo - 93400 - Saint-Ouen-sur-Seine
or, where applicable, send an e-mail to ROAMANCE's Data Protection Officer at the following address:
GDPR@roamance.io
Frequently asked questions
Why choose Roamance?
Roamance stands out for its competitive pricing, excellent network coverage in over 140 countries, instant activation, no hidden fees and multilingual customer support from 8 AM to 8 PM, 6 days a week. Our app is user-friendly and our flexible offers can be reused for future trips.
Does the eSIM work in every country?
Almost everywhere. Roamance covers more than 140 destinations. Check availability for your country in the "Our Packages" section, under "Countries".
What happens if I change my phone?
You can reinstall your eSIM profile on your new device. Just scan the QR code again or transfer it via your account.
Is it complicated to install?
Not at all. Everything happens directly on your phone. After your purchase, you receive a QR code that you can scan or install manually in just a few steps. Activation then happens automatically in your device settings. And if you need help, our support team is there to guide you.